Original URL: http://www.reghardware.co.uk/2006/02/22/macosx_vuln/
Security researchers have discovered a vulnerability (http://secunia.com/advisories/18963) in Mac OS X that creates a means for hackers to compromise vulnerable systems. The critical security flaw is unpatched but workarounds have been issued.
The flaw stems from errors in the processing of metadata file association meta data in ZIP archives. By renamed "safe file" extensions stored in ZIP archives, hackers could trick users into executing malicious shell scripts. The security bug might also be used to attack Apple Safari browser users by creating a means for attackers to automatically run malign code when a Safari user visits a malicious-constructed website, an even more potent exploit scenario.
The vulnerability has been confirmed on a fully patched system with Safari 2.0.3 and Mac OS X 10.4.5. Early versions might also be affected. Security notification firm Secunia has published a test here (http://secunia.com/mac_os_x_command_execution_vulnerability_test). It advises users to protect themselves against exploit by disabling the "Open safe files after downloading" option in Safari. Mac users should also avoid opening files in Zip archives that originate from untrusted sources.
"This is yet another example of the continuing spread of malicious code onto other platforms," said Alfred Huger, senior director of engineering at Symantec Security Response. "While there is no known exploit at this time, users are encouraged to turn off the 'Open safe files after downloading option' in their Safari browsers and watch for further information from Apple."
Discovery of the vulnerability follows last week's discovery of two low-level worms targeting Mac OS X: Leap-A and Inqtana-A. ®
Apple updates to defend against OS, app and QuickTime flaws (15 May 2006)
http://www.theregister.co.uk/2006/05/15/apple_update/
Plug pulled on Mac hacking challenge (9 March 2006)
http://www.theregister.co.uk/2006/03/09/mac_hacking_challenge/
Apple update fixes 'critical' security bug (2 March 2006)
http://www.reghardware.co.uk/2006/03/02/apple_security_update/
Triple threat to Mac OS X largely academic (27 February 2006)
http://www.theregister.co.uk/2006/02/27/apple_security_threats_a_reality/
Sophos in Mac OS X worm false alarm (23 February 2006)
http://www.theregister.co.uk/2006/02/23/sophos_false_positive/
Apple to 'launch full movie downloads' next week (23 February 2006)
http://www.reghardware.co.uk/2006/02/23/apple_itunes_movies/
Mac OS X malware latches onto Bluetooth vulnerability (17 February 2006)
http://www.theregister.co.uk/2006/02/17/macosx_bluetooth_worm/
'First' Mac OS X Trojan sighted (16 February 2006)
http://www.theregister.co.uk/2006/02/16/mac_os-x_virus/
Patch posted to run Mac OS X 10.4.4 on 'generic PC' (15 February 2006)
http://www.reghardware.co.uk/2006/02/15/macosx_intel_generic_pc_patch/
Firefox and Mac security sanctuaries 'under attack' (19 September 2005)
http://www.theregister.co.uk/2005/09/19/symantec_threat_report/
Symantec false alert floors Macs (10 May 2005)
http://www.theregister.co.uk/2005/05/10/symantec_mac_false_alarm/